Skip to main content

CWE archive

CWE-330 CVEs

Programmatic archive

380 CVEs tagged with CWE-33075 Critical, 129 High, 147 Medium, 29 Low, 0 Unrated.

CVE-2017-5242

Published Jan 12, 2023

Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26407

Published Jan 11, 2023

A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25089

Published Dec 27, 2022

A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file src/muon/handler.clj. Th…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-4277

Published Dec 25, 2022

A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Fi…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-4248

Published Dec 18, 2022

A vulnerability was found in kapetan dns up to 6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file DNS/Protocol/Request.cs. T…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46353

Published Dec 13, 2022

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V…

CVSS 9.8 · Critical

CVE-2022-44938

Published Dec 8, 2022

Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-4241

Published Nov 15, 2022

A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation le…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-4240

Published Nov 15, 2022

A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The man…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3959

Published Nov 11, 2022

A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is some unknown functionality of the component Session Hash Hand…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-36022

Published Nov 10, 2022

Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44795

Published Nov 7, 2022

An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30935

Published Sep 28, 2022

An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This al…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-36536

Published Sep 16, 2022

An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating cr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40299

Published Sep 9, 2022

In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the privileges of other users via a procedure in a file under /tm…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36045

Published Aug 31, 2022

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notificati…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-37400

Published Aug 15, 2022

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30629

Published Aug 10, 2022

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive con…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-24406

Published Jul 27, 2022

OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 380 CVEsPage 6 of 16